Database View Vulnerability in MongoDB Connector for BI
CVE-2026-81490

8.3HIGH

Key Information:

Vendor

Mongodb

Vendor
CVE Published:
28 August 2026

What is CVE-2026-81490?

A database user can create a view within a namespace that disrupts the schema sampling routine of the MongoDB Connector for BI. When a view is defined whose evaluation results in consistent failures, the sampling logic misclassifies the server message as transient. Consequently, after the configured number of retries is reached, the system continues its operation without a valid schema. This leads to a scenario where SQL clients are unable to retrieve any results, effectively halting data integration until the problematic view is removed or its namespace is excluded from the sampling process.

Affected Version(s)

BI Connector 0 < 2.14.31

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.